WO2020233496A1 - Procédé et appareil de session sécurisée - Google Patents

Procédé et appareil de session sécurisée Download PDF

Info

Publication number
WO2020233496A1
WO2020233496A1 PCT/CN2020/090240 CN2020090240W WO2020233496A1 WO 2020233496 A1 WO2020233496 A1 WO 2020233496A1 CN 2020090240 W CN2020090240 W CN 2020090240W WO 2020233496 A1 WO2020233496 A1 WO 2020233496A1
Authority
WO
WIPO (PCT)
Prior art keywords
rate
network element
access network
integrity protection
session
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/090240
Other languages
English (en)
Chinese (zh)
Inventor
李飞
张博
孙海洋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Publication of WO2020233496A1 publication Critical patent/WO2020233496A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/10Integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]

Definitions

  • This application relates to the field of wireless communication, and more specifically, to a secure conversation method and device.
  • 5G 5th Generation
  • access network equipment such as base stations
  • integrity protection consumes a lot of network performance, it can be determined whether to perform integrity protection according to business characteristics. Generally, for service data with high accuracy requirements, integrity protection is required between terminal equipment and access network equipment; for service data with low accuracy requirements, the terminal equipment and access network equipment may not Perform integrity protection.
  • the present application provides a secure conversation method and device, in order to consider more application scenarios, meet different business requirements, and improve user experience.
  • a secure conversation method is provided.
  • the method may be executed by the access network device, or may also be executed by a chip or circuit configured in the access network device, which is not limited in this application.
  • the method may include: the access network device receives a session request message sent by the session management network element, the session request message carries the user plane security policy of the terminal device and the first rate information; In the case that the first rate executes the user plane security policy, the access network device activates integrity protection at a second rate, where the second rate is lower than the first rate.
  • the access network device in the case that the access network device cannot execute the user plane security policy at the first rate, in other words, the access network device’s capability cannot perform integrity protection on the session and is based on the rate required by the session (for example, In the case of performing services at the first rate, in other words, when the access network device cannot activate integrity protection at the first rate, the access network device can perform at a rate lower than the first rate (for example, record As the second rate), the integrity protection is activated, and then another solution is proposed by considering the application scenarios of various services, which can provide another option to meet the needs of different services as much as possible and match more applications Scene to improve user experience.
  • the inability of the access network device to execute the user plane security policy at the first rate includes: the access network device cannot simultaneously enable integrity protection and perform data transmission at the first rate. Then in this case, integrity protection can be turned on first; then, within the capability, data transmission is performed at the second rate, where the second rate is lower than the first rate.
  • the access network device activates integrity protection at a second rate, which may indicate that the access network device activates integrity protection at any rate lower than the first rate; or, it may also be expressed as, The access network device activates integrity protection and reduces the rate; or, it can also mean that the access network device activates integrity protection at a certain rate.
  • the second rate is less than or equal to the maximum transmission rate currently supported by the access network device.
  • the second rate is used to transmit service data with the terminal device.
  • the second rate is less than the rate required by the session (for example, recorded as the first rate), or the second rate may be the maximum transmission rate currently supported by the access network device, or the second rate may also be less than the current rate of the access network device The maximum transmission rate that can be supported.
  • the access network device activating integrity protection at a second rate includes: based on the user plane security policy, the access network device is The second rate activates integrity protection.
  • the access network device can activate integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate according to the user plane security policy of the terminal device.
  • the user plane security policy of the terminal device is used to instruct: in the case where the access network device cannot execute the user plane security policy at the first rate, the access network device is The second rate activates integrity protection.
  • the existing security policy can be improved, and a way to turn on the integrity protection when the integrity protection conflicts with the service rate is added.
  • the following examples are described in detail.
  • the user plane security policy of the terminal device is determined by the session management network element or the unified data management network element.
  • the user plane policy of the terminal device may be determined by the session management network element, or may be determined by the unified data management network element, which is not limited.
  • the session request message further includes indication information; the access network device activating integrity protection at a second rate includes: based on the indication information, The access network device activates integrity protection according to the second rate.
  • the access network device can activate the integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate according to the instruction information.
  • the access network device receives instruction information from any one of the following devices: the session management network element, the unified data management network element, or the terminal device, wherein the instruction information is used to indicate:
  • the access network device activates integrity protection at the second rate.
  • the indication information may be indicated by any one of the session management network element, the unified data management network element, or the terminal device.
  • the access network device activating integrity protection at a second rate includes: when it is determined that the session meets a preset condition, the access The network device activates integrity protection at the second rate.
  • the access network device can determine by itself whether to activate the integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate. For example, it can be determined according to the session type or service type, whether to activate the integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate.
  • the secure session method further includes: the access network device receives rate information from a policy control network element, where the rate information is used to indicate the second Two rate.
  • the access network device can control the rate information of the network element based on the policy to determine the transmission rate when transmitting service data with the terminal device.
  • the secure session method further includes: the access network device sends the second rate information to the session management network element.
  • a secure conversation method is provided.
  • the method may be executed by the session management network element, or may also be executed by a chip or circuit configured in the session management network element, which is not limited in this application.
  • the method may include: the session management network element determines a user plane security policy of the terminal device, where the user plane security policy is used to indicate: when the access network device cannot execute the user plane security policy at the first rate, The access network device activates integrity protection at a second rate, where the second rate is lower than the first rate; the session management network element sends the user plane security policy to the access network device.
  • the session management network can determine the user plane security policy of the terminal device, and the user plane security policy can be used to indicate that when the access network device cannot execute the user plane security policy at the first rate, in other words .
  • the access network device When the access network device’s capabilities cannot protect the integrity of the session and provide services at the rate required by the session, in other words, when the access network device cannot activate integrity protection at the first rate, the access The network access device can activate integrity protection at a rate lower than the first rate (for example, denoted as the second rate), and then by considering the application scenarios of various services, another solution is proposed, which can provide yet another option. It is convenient to meet the needs of different businesses as much as possible, match more application scenarios, and improve user experience.
  • integrity protection must be performed for certain services, or integrity protection is not performed for certain services, or integrity protection is discarded when integrity protection conflicts with the service rate.
  • This method is too absolute. For some services, it is better to implement integrity protection. However, if integrity protection is really not possible, and occasional packet loss and tampering will not affect the service transmission, then for this service, the existing The regulations will affect user experience and reduce transmission performance.
  • the session management network element obtains the subscription information of the terminal device; the session management network element determines the user plane security policy of the terminal device, including: The session management network element determines the user plane security policy of the terminal device based on the subscription information of the terminal device.
  • the session management network element can determine the user plane security policy of the terminal device based on the subscription information of the terminal device, or, based on the subscription information of the terminal device, determine whether the access network device should execute the user at the first rate.
  • the integrity protection is activated at the second rate, so that the integrity protection policy can be dynamically adjusted to match more application scenarios.
  • the session management network element determining the user plane security policy of the terminal device includes: the session management network element according to the session request message of the terminal device , Determine the user plane security policy of the terminal device.
  • the session management network element can determine the user plane security policy of the terminal device based on the session request message of the terminal device, or, based on the session request message of the terminal device, determine whether the access network device is unable to follow the first rate
  • the integrity protection is activated at the second rate, so that the integrity protection policy can be dynamically adjusted according to the session request message, thereby improving data transmission performance as much as possible and improving user experience.
  • the secure session method further includes: the session management network element receives rate information provided by the policy control network element; based on the rate information, the The session management network element sends the information used to indicate the second rate to the access network device.
  • the secure session method further includes: the session management network element receiving the second rate information sent by the access network device.
  • a secure conversation method is provided.
  • the method may be executed by the session management network element, or may also be executed by a chip or circuit configured in the session management network element, which is not limited in this application.
  • the method may include: a session management network element receives a session creation session management context service request initiated by an access and mobility management network element; based on the session creation session management context service request, the session management network element returns the session to the AMF Create a session management context service response, the session creation session management context service response includes indication information used to indicate: when the access network device cannot execute the user plane security policy at the first rate, the access The network access device activates integrity protection at a second rate, where the second rate is lower than the first rate.
  • the session management network element can create a session management context service request based on the session provided by the invoking access and mobility management network element to determine whether to instruct the access network device, where the access network device cannot execute the user at the first rate
  • a security policy in other words, when the access network device’s capabilities cannot protect the integrity of the session and provide services at the rate required by the session, in other words, the access network device cannot perform the first
  • the access network device can activate integrity protection at a rate lower than the first rate (for example, recorded as the second rate), and then by considering the application scenarios of various services, another method is proposed.
  • the solution in turn, can provide another option to meet the needs of different services as much as possible, match more application scenarios, and improve user experience.
  • the session management network element receiving the session creation session management context service request initiated by the access and mobility management network element includes: the session management network element receives the packet data unit ( packet data unit, PDU) Session creation session management context service request.
  • the session management network element receives the packet data unit ( packet data unit, PDU) Session creation session management context service request.
  • the session management network element returning a session creation session management context service response to the access and mobility management network element includes: the session management network element returning a PDU session to the access and mobility management network element Create a session management context service response.
  • the session creation session management context service request includes notification information, and the notification information is used to notify that the access network device cannot follow the first rate
  • the access network device activates integrity protection at the second rate
  • the method further includes: based on the notification information, the session management network element determines the indication information.
  • the terminal device can determine by itself whether the access network device needs to activate the integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate, so as to better meet the requirements user experience.
  • the terminal device determines that the access network device needs to activate the integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate, it can notify the session management network element, and then the session The management network element notifies the access network device.
  • the session creation session management context service request includes information about the service type of the terminal device; the secure session method further includes: based on the service type Information, the session management network element determines the indication information.
  • the session management network element can determine whether the access network device needs to activate the integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate according to the service type. Meet the needs of different businesses.
  • the secure session method further includes: the session management network element receives rate information provided by the policy control network element; based on the rate information, the session management The network element determines the second rate.
  • the secure session method further includes: the session management network element receiving the second rate information sent by the access network device.
  • a secure conversation method is provided.
  • the method may be executed by a terminal device, or may also be executed by a chip or a circuit configured in the terminal device, which is not limited in this application.
  • the method may include: the terminal device determines indication information, the indication information is used to indicate: in the case that the access network device cannot execute the user plane security policy at the first rate, the access network device activates complete at the second rate Protection, wherein the second rate is lower than the first rate; the terminal device sends the indication information to the access and mobility management network element.
  • the terminal device can determine by itself whether the access network device needs to implement the user plane security policy at the first rate. In other words, determine whether the access network device needs to be on the access network.
  • the integrity protection is activated at a rate lower than the first rate (for example, the second rate), so that the user experience can be better satisfied.
  • the terminal device determines that the access network device needs to activate the integrity protection at the second rate when the access network device cannot activate the integrity protection at the first rate, it can notify the session management network element to facilitate the session management network element Notify the access network equipment.
  • a secure conversation device which includes various modules or units for executing the method in any one of the foregoing first to fourth aspects.
  • a secure conversation device including a processor.
  • the processor is coupled with the memory and can be used to execute instructions in the memory to implement the method in any one of the possible implementation manners of the first to fourth aspects.
  • the secure conversation device further includes a memory.
  • the secure conversation device further includes a communication interface, and the processor is coupled with the communication interface.
  • the secure session device is a communication device, such as a terminal device, a session management network element or an access network device in the embodiment of the present application.
  • the communication interface may be a transceiver, or an input/output interface.
  • the secure session device is a chip configured in a communication device, such as a chip configured in a terminal device, a session management network element, or an access network device in the embodiment of the present application.
  • the communication interface may be an input/output interface.
  • the transceiver may be a transceiver circuit.
  • the input/output interface may be an input/output circuit.
  • a processor including: an input circuit, an output circuit, and a processing circuit.
  • the processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor executes the method in any one of the possible implementation manners of the first to fourth aspects.
  • the foregoing processor may be a chip
  • the input circuit may be an input pin
  • the output circuit may be an output pin
  • the processing circuit may be a transistor, a gate circuit, a flip-flop, and various logic circuits.
  • the input signal received by the input circuit may be received and input by, for example, but not limited to, a receiver
  • the signal output by the output circuit may be, for example, but not limited to, output to and transmitted by the transmitter
  • the circuit can be the same circuit, which is used as an input circuit and an output circuit at different times.
  • the embodiments of the present application do not limit the specific implementation manners of the processor and various circuits.
  • a processing device including a processor and a memory.
  • the processor is used to read instructions stored in the memory, and can receive signals through a receiver and transmit signals through a transmitter, so as to execute the method in any one of the possible implementation manners of the first to fourth aspects.
  • processors there are one or more processors and one or more memories.
  • the memory may be integrated with the processor, or the memory and the processor may be provided separately.
  • the memory can be a non-transitory (non-transitory) memory, such as a read only memory (ROM), which can be integrated with the processor on the same chip, or can be set in different On the chip, the embodiment of the present application does not limit the type of memory and the setting mode of the memory and the processor.
  • ROM read only memory
  • sending instruction information may be a process of outputting instruction information from the processor
  • receiving capability information may be a process of the processor receiving input capability information.
  • the processed output data may be output to the transmitter, and the input data received by the processor may come from the receiver.
  • the transmitter and receiver can be collectively referred to as a transceiver.
  • the processing device in the above eighth aspect may be a chip, and the processor may be implemented by hardware or software.
  • the processor When implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc.; when implemented by software
  • the processor may be a general-purpose processor, which is implemented by reading software codes stored in the memory.
  • the memory may be integrated in the processor, may be located outside the processor, and exist independently.
  • a computer program product includes: a computer program (also called code, or instruction), which when the computer program is run, causes the secure conversation device to execute the first to The method in any possible implementation manner in the fourth aspect.
  • a computer program also called code, or instruction
  • a computer-readable medium stores a computer program (also called code, or instruction) when it runs on a secure conversation device, so that the secure conversation device executes the first
  • a computer program also called code, or instruction
  • a system including the aforementioned terminal device, session management network element, and access network device.
  • FIG. 1 is a schematic diagram of a network architecture suitable for the method provided by the embodiment of the present application
  • Fig. 2 is a schematic diagram of a secure session method provided according to an embodiment of the present application.
  • FIG. 3 is a schematic flowchart of a secure session method provided by another embodiment of the present application.
  • FIG. 4 is a schematic flowchart of a secure session method provided by another embodiment of the present application.
  • FIG. 5 is a schematic flowchart of a secure session method provided by still another embodiment of the present application.
  • FIG. 6 is a schematic flowchart of a secure session method provided by another embodiment of the present application.
  • FIG. 7 is a schematic flowchart of a secure session method provided by still another embodiment of the present application.
  • FIG. 8 is a schematic block diagram of a secure conversation device provided by an embodiment of the present application.
  • Fig. 9 is a schematic block diagram of a secure conversation device provided by an embodiment of the present application.
  • GSM Global System of Mobile Communication
  • CDMA Code Division Multiple Access
  • WCDMA Wideband Code Division Multiple Access
  • GSM Global System of Mobile Communication
  • GPRS General Packet Radio Service
  • LTE Long Term Evolution
  • FDD Frequency Division Duplex
  • TDD Time Division Duplex
  • UMTS Universal Mobile Telecommunication System
  • WiMAX Worldwide Interoperability for Microwave Access
  • the embodiments of the application do not specifically limit the specific structure of the execution body of the method provided in the embodiments of the application, as long as the program that records the code of the method provided in the embodiments of the application can be executed according to the embodiments of the application.
  • the provided method can be used for communication.
  • the execution subject of the method provided in the embodiments of the present application may be a terminal or a network-side device, or a functional module in a UE or a network-side device that can call and execute the program.
  • FIG. 1 is a schematic diagram of a network architecture suitable for the method provided by the embodiment of the present application.
  • the network architecture may be a non-roaming architecture, for example.
  • the network architecture may specifically include the following network elements:
  • User equipment it can be called terminal equipment, terminal, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile equipment, user terminal, wireless communication equipment, User agent or user device.
  • the terminal device can also be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a wireless local loop (Wireless Local Loop, WLL) station, a personal digital processing (Personal Digital Assistant, PDA), with wireless communication Functional handheld devices, computing devices, or other processing devices connected to wireless modems, in-vehicle devices, wearable devices, terminal devices in the future 5G network, or future evolution of the public land mobile network (Public Land Mobile Network, PLMN) Terminal equipment, etc., this embodiment of the application does not limit this.
  • SIP Session Initiation Protocol
  • WLL Wireless Local Loop
  • PDA Personal Digital Assistant
  • Access network Provides network access functions for authorized users in a preset area, and can use transmission tunnels of different quality according to user levels and service requirements.
  • the access network may be an access network using different access technologies.
  • 3rd Generation Partnership Project 3rd Generation Partnership Project
  • 3GPP 3rd Generation Partnership Project
  • non-3GPP non-third generation Generation Partnership Project
  • 3GPP access technology refers to the access technology that complies with the 3GPP standard specifications.
  • the access network that adopts the 3GPP access technology is called the radio access network (Radio Access Network, RAN), among which the access network equipment in the 5G system Next generation Node Base station (gNB).
  • RAN radio access network
  • a non-3GPP access technology refers to an access technology that does not comply with the 3GPP standard specifications, for example, an air interface technology represented by an access point (AP) in wifi.
  • AP access point
  • An access network that implements access network functions based on wireless communication technology may be called a radio access network (RAN).
  • the wireless access network can manage wireless resources, provide access services for the terminal, and complete the forwarding of control signals and user data between the terminal and the core network.
  • the wireless access network can be, for example, the Global System of Mobile Communications (GSM) system or the Base Transceiver Station (BTS) in Code Division Multiple Access (CDMA), or it can be a broadband code division.
  • the base station (NodeB, NB) in the Wideband Code Division Multiple Access (WCDMA) system can also be the evolved base station (Evolutional NodeB, eNB or eNodeB) in the LTE system, or the cloud wireless access network (Cloud Radio Access Network, CRAN) scenario wireless controller, or the network device can be a relay station, access point, in-vehicle device, wearable device, network device in the future 5G network or network device in the future evolved PLMN network, etc.
  • the embodiments of this application are not limited.
  • Access and mobility management function (AMF) entities mainly used for mobility management and access management, etc., and can be used to implement mobility management entity (mobility management entity, MME) functions in addition to sessions Functions other than management, for example, lawful interception, or access authorization (or authentication) functions. In the embodiment of the present application, it can be used to realize the functions of accessing and mobility management network elements.
  • MME mobility management entity
  • Session management function (SMF) entity mainly used for session management, UE's Internet Protocol (IP) address allocation and management, selection of manageable user plane functions, policy control, or charging function interfaces End point and downlink data notification, etc. In the embodiment of this application, it can be used to realize the function of the session management network element.
  • IP Internet Protocol
  • User Plane Function (UPF) entity that is, the data plane gateway. It can be used for packet routing and forwarding, or quality of service (QoS) processing of user plane data, etc.
  • User data can be connected to the data network (DN) through this network element. In the embodiment of this application, it can be used to realize the function of the user plane gateway.
  • DN data network
  • Data network A network used to provide data transmission.
  • DN Data network
  • An operator s business network, an Internet network, a third-party business network, etc.
  • Authentication server function authentication server function, AUSF
  • AUSF authentication server function
  • Network exposure function (NEF) entity used to safely open services and capabilities provided by 3GPP network functions to the outside.
  • Network storage function (NF) repository function (NRF) entity used to store network function entities and description information of the services they provide, and support service discovery, network element entity discovery, etc.
  • PCF Policy control function
  • Unified data management (UDM) entity used for unified data management, 5G user data management, processing user identification, access authentication, registration, or mobility management, etc.
  • Application function (AF) entity used to route data affected by applications, access network open function network elements, or interact with policy frameworks for policy control, etc.
  • the N1 interface is the reference point between the terminal and the AMF entity;
  • the N2 interface is the reference point between the AN and AMF entities, used for non-access stratum (NAS) message transmission, etc.;
  • N3 The interface is the reference point between the (R)AN and the UPF entity, used to transmit user plane data, etc.;
  • the N4 interface is the reference point between the SMF entity and the UPF entity, used to transmit, for example, the tunnel identification information and data of the N3 connection Cache indication information, downlink data notification message and other information;
  • N6 interface is the reference point between UPF entity and DN, used to transmit user plane data, etc.
  • the above-mentioned network architecture applied to the embodiments of the present application is only an example of a network architecture described from the perspective of a traditional point-to-point architecture and a service-oriented architecture, and the network architecture applicable to the embodiments of the present application is not limited thereto. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiments of the present application.
  • AMF entity, SMF entity, UPF entity, NSSF entity, NEF entity, AUSF entity, NRF entity, PCF entity, and UDM entity shown in Figure 1 can be understood as network elements used to implement different functions in the core network. , For example, can be combined into network slices on demand. These core network elements may be independent devices, or they may be integrated in the same device to implement different functions, which is not limited in this application.
  • the entity used to implement AMF is referred to as the access and mobility management network element
  • the entity used to implement SMF is referred to as the session management network element
  • the entity used to implement UPF is referred to as the user plane gateway.
  • the entity used to implement the UDM function is recorded as a unified data management network element
  • the entity used to implement the PCF is recorded as a policy control network element.
  • the name of the interface between the various network elements in FIG. 1 is only an example, and the name of the interface in a specific implementation may be other names, which is not specifically limited in this application.
  • the name of the message (or signaling) transmitted between the various network elements is only an example, and does not constitute any limitation on the function of the message itself.
  • Integrity protection The sender performs integrity protection on the plaintext or ciphertext according to the integrity protection algorithm and the integrity protection key.
  • the receiving end can perform integrity verification on the integrity-protected data according to the same integrity protection algorithm and integrity protection key.
  • the integrity protection key can be generated after the receiving end receives the access layer security mode command AS SMC (generated according to the user plane integrity protection algorithm carried in the AS SMC), or when integrity protection needs to be turned on Generated (generated according to the user plane integrity protection algorithm carried in the AS SMC).
  • Security capabilities including but not limited to: security algorithms, security parameters, keys, etc.
  • the security capability may include, for example, the security capability of the UE and the security capability of the user plane gateway.
  • Security algorithm the algorithm used for data security protection. For example, it may include: encryption/decryption algorithms, integrity protection algorithms, etc.
  • activating user plane security protection it can be understood as turning on the security protection function.
  • activating user plane security protection includes activating integrity protection. For example, when integrity protection is activated, the integrity protection function is turned on. On the contrary, the integrity protection is not activated, that is, the integrity protection function is not activated. When certain safety protection is activated, the corresponding safety protection can be directly activated.
  • activating user plane security protection may also include activating encryption/decryption protection, integrity verification, and the like.
  • the user plane gateway may be the integrity protection terminal, and activating the user plane security protection may include activating integrity protection; the terminal device may be the integrity verification terminal, and the activation User plane security protection may include activation integrity verification.
  • the terminal device may be an integrity protection terminal, and activating user plane security protection may include activating integrity protection; the user plane gateway may be an integrity verification terminal, and activating user plane security protection may include activating integrity verification.
  • the terminal device can serve as the integrity protection terminal and the integrity verification terminal at the same time;
  • the user plane gateway can serve as the integrity protection terminal and the integrity verification terminal at the same time. If integrity protection/verification is activated, the terminal device and the user plane gateway can both activate integrity protection and integrity verification.
  • Security policy at least can be used to indicate whether to activate encryption protection and/or integrity protection.
  • the security policy can also be used to indicate other more information, such as strength recommendations of the security algorithm, etc., the specific content of which is not limited in this embodiment of the application.
  • a security policy or it can also be called a user-plane security policy, and is described in a unified manner below.
  • the security policy may indicate the preference of security protection, for example, may indicate required (required), recommended (preferred) and not required (not needed) security protection. Based on the security protection preference, it can be determined whether to activate encryption protection and/or integrity protection.
  • integrity protection must be performed between the terminal equipment and the access network equipment (such as the base station). If the access network device does not support its own capabilities, it directly refuses the establishment of the corresponding service session. For example, for the business of reporting measurement data, the accuracy of the data is very important, and it will have a great impact if it is tampered with, so it is necessary to turn on the protection.
  • integrity protection is given priority between the terminal equipment and the access network equipment.
  • integrity protection will be used when the access network equipment’s capabilities can support integrity protection. It will not be done when integrity protection is not supported.
  • the access network device can support integrity protection, but it cannot be enabled due to load and other reasons.
  • a rate of 1 Mbps is also supported.
  • the access network device will choose to turn off the integrity protection to meet the 1Mbps rate requirement.
  • preferred means that the access network device can only enable integrity protection only when it can meet the service rate requirements and can also support integrity protection. Or, it can also be understood as when the rate and integrity protection When the two can only choose one, the rate will be satisfied first and the integrity protection will be turned off.
  • the security policy corresponding to required may be recorded as the first policy
  • the security policy corresponding to not needed may be recorded as the second policy
  • the security policy corresponding to preferred may be recorded as the third policy.
  • the first strategy, the second strategy, and the third strategy are only names for distinction, and do not limit the protection scope of the embodiments of the present application.
  • the existing security strategy basically considers three situations: integrity protection (for example, recorded as the first strategy), incomplete protection (for example, recorded as the second strategy), and integrity protection and service rate conflict Integrity protection is discarded from time to time to maintain the rate (for example, recorded as the third strategy).
  • the embodiment of the present application proposes a secure session method so as to be able to match more business scenarios.
  • the drawings are merely illustrative for ease of understanding, and should not constitute any limitation to the application.
  • the gNB shown in the figure can correspond to access network equipment
  • AMF can correspond to access and mobility management network elements
  • SMF can correspond to session management network elements
  • UDM can correspond to unified data management network elements
  • PCF can correspond to For policy management network elements.
  • the name of each network element is only defined for distinguishing different functions, and should not constitute any limitation in this application. This application does not exclude the possibility of defining other network elements to achieve the same or similar functions.
  • FIG. 2 is a schematic interaction diagram of a method 200 provided by an embodiment of the present application.
  • the method 200 may include the following steps.
  • the access network device receives a session request message sent by the session management network element, where the session request message carries the user plane security policy of the terminal device and the first rate information.
  • the first rate can be used to indicate the rate required by the session, or, in other words, it can be used to indicate the rate required by the session when the access network device executes the user plane security policy, or, in other words, can be used for Indicates the rate required by the session when the access network device activates integrity protection, or, in other words, can be used to indicate the transmission rate that the access network device needs to meet when the integrity protection of the session is performed, or, in other words, it can Used to indicate the transmission rate required by the terminal device when the access network device performs integrity protection on the session.
  • the first rate is used to express.
  • the user-plane security policy may include the user-plane security policy contained in the subscription information in the prior art, such as required, not needed, and preferred as described above.
  • the user-plane security policy may also include another policy. For distinction, Record this strategy as the fourth strategy.
  • the fourth strategy can be at least one of the following two forms.
  • Form 1 The fourth strategy can be used to indicate that integrity protection is preferred when the rate conflicts with integrity protection.
  • the fourth strategy can be used to indicate that when the capabilities of the access network device do not support the service required capabilities of the terminal device, or in other words, the capabilities of the access network device cannot protect the integrity of the session and are based on session
  • the access Network equipment chooses to turn on integrity protection.
  • the fourth strategy can be used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, and the access network device transmits at the maximum rate currently available.
  • the fourth strategy can be used to indicate that when the capabilities of the access network device do not support the service required capabilities of the terminal device, or in other words, the capabilities of the access network device cannot protect the integrity of the session and are based on session
  • the access network device chooses to enable integrity protection, and the access network device transmits data with the terminal device at the maximum rate currently available.
  • the access network device receives the session request message, or, alternatively, the access network device receives the service request message. Based on the session request message or service request message, the access network can perform corresponding data transmission with the terminal device.
  • the access network device When the access network device cannot execute the user plane security policy at the first rate, the access network device activates integrity protection at a second rate, where the second rate is lower than the first rate.
  • the access network device After the access network device receives the session request message, if the access network device’s capability is unable to protect the integrity of the session and the session is served at the rate (for example, the first rate), it will choose to activate integrity protection, but the service will be performed at a rate lower than the first rate.
  • the rate for example, the first rate
  • the access network device In the case that the access network device cannot execute the user plane security policy at the first rate, the access network device activates integrity protection at the second rate. It can also be understood that the access network device cannot execute the user plane security policy at the first rate. In the case of a security policy, the access network device reduces the rate and activates integrity protection; or, it can also be understood as, when the access network device cannot execute the user plane security policy at the first rate, the access network device activates Integrity protection; Or, it can also be understood that, in the case of a conflict between rate and integrity protection, the access network device chooses to implement integrity protection.
  • the second rate is used to indicate a rate lower than the first rate. That is to say, when the integrity protection is activated, the transmission rate of the access network device is lower than the first rate.
  • the second rate may be a rate determined by the access network device itself, or may be a rate indicated by other network elements, which is not limited.
  • the access network device In the case that the access network device cannot execute the user plane security policy according to the first rate, the access network device activates integrity protection, which can be implemented at least in any of the following three ways; in other words, the access network device Based on any one of the following methods, it may be determined whether to activate the integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate.
  • integrity protection can be implemented at least in any of the following three ways; in other words, the access network device Based on any one of the following methods, it may be determined whether to activate the integrity protection at the second rate when the access network device cannot execute the user plane security policy at the first rate.
  • the user plane security policy of the terminal device carried in the session request message is the fourth policy, and the fourth policy may be any of the foregoing forms.
  • the access network device determines based on the fourth policy that the integrity protection is activated when the access network device cannot execute the user plane security policy at the first rate.
  • the fourth policy may be determined by the session management network element.
  • the session management network element determines the fourth strategy, and sends information about the fourth strategy to the access network device.
  • the fourth strategy may be determined by a unified data management network element.
  • the unified data management network element determines the fourth policy and sends information about the fourth policy to the session management network element.
  • the session management network element receives the fourth policy provided by the unified data management network element.
  • the session management network element may directly send the information of the fourth strategy to the access network device.
  • the session management network element may also first determine whether to implement the fourth strategy, and when it is determined that the fourth strategy can be implemented, send the information of the fourth strategy to the access network device.
  • the session management network element may determine whether the fourth policy can be implemented based on the service type and/or the capabilities of the access network device.
  • Manner B When the access network device cannot execute the user plane security policy at the first rate, the access network device activates integrity protection based on the instruction information.
  • the instruction information is used to indicate: when the access network device cannot execute the user plane security policy at the first rate, the access network device activates integrity protection, or the access network device cannot execute the user plane security policy at the first rate. In the case of a security policy, integrity protection is activated at the second rate.
  • the indication information may be determined by the terminal device.
  • the terminal device determines whether the access network device wants to activate integrity protection when the access network device cannot execute the user plane security policy at the first rate, and instructs the access network device.
  • the instruction information may be sent to the access network device through separate signaling, for example, forwarded to the access network device through the session management network element; the instruction information may also be carried in the session request message, which is not limited.
  • the indication information may be determined by the session management network element.
  • the session management network element determines that when the access network device cannot execute the user plane security policy at the first rate, the access network device activates integrity protection, whether the access network device needs to activate the integrity protection, and reports Access network equipment instructions.
  • the instruction information can be sent to the access network device through separate signaling; the instruction information can also be carried in the session request message, such as the session management context returned by the session management network element to the access and mobility management network element. In the service response, this is not limited.
  • the indication information may be determined by a unified data management network element.
  • the unified data management network element determines whether the access network device activates integrity protection when the access network device cannot execute the user plane security policy at the first rate, and whether the access network device needs to activate integrity protection, and Instruct to the access network equipment.
  • the instruction information may be sent to the access network device through separate signaling, for example, forwarded to the access network device through the session management network element; the instruction information may also be carried in the session request message, which is not limited.
  • Manner C The access network device determines to activate the integrity protection when the user plane security policy cannot be executed at the first rate.
  • the access network device determines whether the session meets the preset condition, and when the session meets the preset condition, the access network device activates integrity protection.
  • the session meets the preset conditions, or it can also be understood that the service meets the preset conditions, for example, the service is a service such as small-capacity voice, or the service is this type of service, that is, the occasional packet loss and tampering have little impact, or The impact of packet loss is less than the preset threshold and so on.
  • the service is a service such as small-capacity voice, or the service is this type of service, that is, the occasional packet loss and tampering have little impact, or The impact of packet loss is less than the preset threshold and so on.
  • the preset condition or the preset threshold may be pre-defined, such as pre-defined by the protocol, or it may be pre-defined by the network device, or it may be notified by the terminal device to the network device, or it may be from The core network is not limited.
  • the access network device receives rate information from the policy control network element, where the rate information is used to indicate the second rate.
  • the access network device reports the second rate to the session management network element.
  • integrity protection can be preferentially selected by self-determination, and the session management network element can be notified, so that the integrity protection strategy can be dynamically adjusted according to the business to match different business scenarios as much as possible.
  • FIG. 3 is a schematic interaction diagram of a method 300 provided by an embodiment of the present application.
  • the method 300 may include the following steps.
  • the terminal device sends a service request message to the access and mobility management network element.
  • the access and mobility management network element receives the service request message from the terminal device.
  • the terminal device initiates a service request message to the access and mobility management network element.
  • the service request message may be used to request the establishment of a connection between the terminal device and the service server of the data network, and the connection with the service server of the data network requested by the service request message may be used to transmit data.
  • the data may be, for example, general data, small data, data corresponding to specific services, etc., which is not limited in this application.
  • the service request message sent by the terminal device to the access and mobility management network element is recorded as the first service request message, which is uniformly represented by the first service request message below.
  • the terminal device may send the first service request message to the access and mobility management network element via the access network device.
  • the first service request message is a service request (service request) message or a packet data unit (packet data unit, PDU) session establishment request (PDU session establishment request) message.
  • service request service request
  • PDU packet data unit
  • PDU session establishment request PDU session establishment request
  • the first service request message may carry slice or specific service-related information, such as service type, single network slice selection assistance information (S-NSSAI), etc., for example, the terminal may be instructed through S-NSSAI The slice information requested by the device.
  • the first service request message may carry a data network name (date network name, DNN) to indicate the data network name that the terminal device requests to access.
  • the first service request message may also be other messages transmitted between the terminal device and the access and mobility management network element.
  • the access and mobility management network element sends a second service request message to the session management network element.
  • the service request message sent by the access and mobility management network element to the session management network element is recorded as the second service request message, which is uniformly represented by the second service request message below.
  • the second service request message may create a session management context service request for the PDU session.
  • step 320 can also be understood as that the session management network element receives the PDU session creation session management context service request initiated by the access and mobility management network element.
  • each network element can transmit messages in a calling manner.
  • the access and mobility management network element sends the second service request message to the session management network element, which can be understood as access Call the session management network element to create a session management context service provided by the session management network element with the mobility management network element. I won't repeat it below.
  • the second service request message may carry the identification of the terminal device.
  • the identification of the terminal equipment may include, but is not limited to, for example: International Mobile Equipment Identity (IMEI), International Mobile Subscriber Identification Number (IMSI), and IP Multimedia Subsystem Private User Identity (IMSI) (IP multimedia subsystem) private user identity, IMPI), temporary mobile subscriber identity (TMSI), IP multimedia public identity (IMPU), media access control (MAC) address , IP address, mobile phone number, globally unique temporary UE identity (GUTI) (for example, for 5G, it can be 5G GUTI), permanent identity (subscription permanent identifier, SUPI), hidden identity ( subscriber concealed identifier (SUCI) or permanent equipment identifier (PEI).
  • IMEI International Mobile Equipment Identity
  • IMSI International Mobile Subscriber Identification Number
  • IMSI IP Multimedia Subsystem Private User Identity
  • IP multimedia subsystem IP multimedia subsystem
  • IMPI temporary mobile subscriber identity
  • TMSI IP multimedia public identity
  • MAC media access control
  • IP address IP address
  • the second service request message may not carry the identification of the terminal device.
  • the previous registration request message has already carried the identification of the terminal device, such as SUPI, 5G GUTI, or PEI.
  • the second service request message may also include DNN, S-NSSAI and other information.
  • the second service request message may also be other messages transmitted between the access and mobility management network element and the session management network element.
  • the session management network element sends a third service request message to the unified data management network element.
  • the service request message sent by the session management network element to the unified data management network element is recorded as the third service request message, which is uniformly represented by the third service request message below.
  • the session management network element calls the user data management acquisition request service provided by the unified data management network element, and obtains the contract information of the terminal device from the unified data management network element.
  • the third service request message may be a subscription request message or a communication message (Nudm_SDM_Get_request) between the session management network element and the unified data management network element.
  • the third service request message may include the identification of the terminal device.
  • identification of the terminal device reference may be made to the description in step 320, which will not be repeated here.
  • the third service request message may also include DNN, S-NSSAI and other information.
  • the third service request message may also be other messages transmitted between the session management network element and the unified data management network element.
  • the unified data management network element sends a third service response message to the session management network element.
  • the third service response message is a response to the third service request message in step 330.
  • the service response message sent by the unified data management network element to the session management network element is recorded as the third service response message, which is uniformly represented by the third service response message below.
  • the unified data management network element finds the subscription information of the terminal device according to the identifier of the terminal device, such as SUPI, and notifies the session management network element of the subscription information through the third service response message. Or, it can also be understood that the unified data management network element returns a third service response message to the session management network element.
  • the third service response message may be a subscription response message or a communication message (Nudm_SDM_Get_response) between the session management network element and the unified data management network element.
  • the contract information of the terminal device may be pre-stored in the unified data management network element.
  • the subscription information may include a user plane (UP) security policy (UP security policy), and the user plane security policy may be used to indicate whether integrity protection needs to be activated.
  • UP security policy user plane security policy
  • the user plane security policy may include the user plane security policy contained in the subscription information in the prior art, such as required, not needed, and preferred as described above.
  • the user plane security policy may also include another Strategy, in order to distinguish, this strategy is recorded as the fourth strategy.
  • the fourth strategy can be at least one of the following two forms.
  • Form 1 The fourth strategy can be used to indicate that integrity protection is preferred when the rate conflicts with integrity protection.
  • the fourth strategy can be used to indicate that when the capabilities of the access network device do not support the service required capabilities of the terminal device, or in other words, the capabilities of the access network device cannot protect the integrity of the session and are based on session
  • the access Network equipment chooses to turn on integrity protection.
  • the subscription information of the terminal device may include a fourth policy, and the fourth policy may be used to indicate that integrity protection is preferentially selected when the rate conflicts with integrity protection.
  • the fourth strategy can be used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, and the access network device transmits at the maximum rate currently available.
  • the conflict between rate and integrity protection includes: integrity protection cannot be turned on when data transmission is performed at the first rate, or data transmission cannot be performed at the first rate when integrity protection is turned on.
  • the fourth strategy can be used to indicate that when the capabilities of the access network device do not support the service required capabilities of the terminal device, or in other words, the capabilities of the access network device cannot protect the integrity of the session and are based on session
  • the access network device chooses to enable integrity protection, and the access network device transmits at the maximum rate currently available.
  • the contract information of the terminal device may include a fourth policy, which may be used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, and to instruct the access network device to use the currently available Maximum rate transmission.
  • the access network equipment cannot execute the user plane security policy at the first rate, which can be used to indicate that the access network equipment will not be able to meet service requirements if it implements integrity protection; or If the access network equipment implements integrity protection, its transmission rate will not meet the transmission rate required by the service; or the rate conflicts with the integrity protection; or the capability of the access network equipment does not support the service requirements of the terminal equipment, etc. .
  • the priority of integrity protection is mentioned many times, which can be used to indicate that in the case that the rate conflicts with the integrity protection, the access network device chooses to implement integrity protection.
  • the access Network equipment can also take some measures to implement integrity protection, such as reducing the transmission rate.
  • the unified data management network element may determine whether to indicate the fourth strategy according to the type of service. For example, for certain services, such as small-capacity voice services, it is of course better to be able to protect the integrity. If integrity protection is really not possible, occasional packet loss and tampering will not affect the understanding of the voice content. Therefore, it can be implemented for this type of service. Fourth strategy.
  • the third service request response may also be other messages transmitted between the session management network element and the unified data management network element.
  • the session management network element determines to implement the fourth policy according to the contract information and/or the local policy (local policy).
  • the session management network element can determine whether the access network device should implement the fourth strategy or determine whether to indicate the fourth strategy according to the subscription information and/or the local policy; The information and/or local strategy determines whether to instruct the access network device. In the case of a conflict between the rate and the integrity protection, the current terminal device requests the session to implement the priority of the integrity protection strategy.
  • the fourth strategy can be any one of Form 1 or Form 2 above.
  • the session management network element determines to implement the fourth strategy, which means that the session management network element indicates the fourth strategy to the access network device, and accordingly, the access network device receives the fourth strategy.
  • integrity protection will be selected first in the case of a conflict between rate and integrity protection.
  • the session management network element determines to implement the fourth strategy, which means that the session management network element indicates the fourth strategy to the access network device, and accordingly, the access network device receives the first strategy.
  • integrity protection will be selected first in the case of a conflict between rate and integrity protection, and the access network equipment will transmit at the maximum rate currently available.
  • the fourth strategy may be instructed by the unified data management network element, or may be instructed by the session management network element, which is not limited. Described below separately.
  • the session management network element obtains the fourth policy from the contract information of the terminal device obtained from the unified data management network element.
  • the session management network element determines whether to implement the fourth policy according to the user plane security policy contained in the subscription information of the terminal device; or, in other words, the fourth policy is instructed by the unified data management network element.
  • the management network element judges whether the fourth strategy can be implemented.
  • the session management network element may generate the first security policy based on the user plane security policy (that is, the fourth policy) contained in the subscription information of the terminal device.
  • the first security policy may include the user plane security policy (that is, the fourth policy), or in other words, the first security policy may be used to indicate that when the rate conflicts with integrity protection, the access network device preferentially selects to enable integrity Protection, or, the first security policy may be used to indicate that when the rate conflicts with integrity protection, the access network device preferentially selects to enable integrity protection, and the access network device transmits at the maximum rate currently available.
  • the session management network element may determine whether the fourth strategy can be implemented based on the service type and/or the capability of the access network device.
  • the session management network element obtains the fourth strategy according to other information.
  • the session management network element determines the fourth strategy according to other information of the terminal device; or, in other words, the fourth strategy is indicated by the session management network element, that is, the session management network element determines whether the fourth strategy can be implemented. If the strategy can be implemented, the session management network element indicates the fourth strategy.
  • the session management network element can also generate a second security policy based on one or more comprehensive judgments of other information, such as local policy, obtained slice-related information, and supported service types, or in other words, determine In the case of a conflict between rate and integrity protection, whether the access network device should give priority to turning on integrity protection.
  • the security requirements of the service type can be obtained from the contract information; it can also interact with other network elements, such as policy control network elements, application service network elements, and so on.
  • the first security policy determined by the session management network element and the user plane security policy obtained from the subscription information of the terminal device may be the same or different, which is not limited in this application.
  • the first security policy or the second security policy is only used to indicate the fourth policy. That is, the items are the same as the information indicated in the existing user plane security policy, but the specific information indicated may be the same or different. However, it should be understood that this application does not exclude the possibility that the first security policy or the second security policy includes other information, such as security capability information, user plane security endpoint information, etc.
  • FIG. 3 only shows a situation where the fourth strategy is determined to be implemented, and the embodiment of the present application is not limited thereto.
  • the session management network element may also determine to implement any of the following strategies: the first strategy, the second strategy, or the third strategy.
  • the method 300 may further include the following steps.
  • the session management network element sends a second service response message to the access and mobility management network element.
  • the second service response message is a response to the second service request message in step 320.
  • the service response message sent by the session management network element to the access and mobility management network element is recorded as the second service response message, which is uniformly represented by the second service response message below.
  • the second service response message may be a PDU session creation session management context service response.
  • step 360 can also be understood as that the session management network element returns a PDU session creation session management context service response to the access and mobility management network element.
  • the second service response message sent by the session management network element to the access and mobility management network element carries the generated first security policy or the second security policy.
  • the second service response message may include the fourth policy.
  • the fourth strategy is used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, or the fourth strategy is used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, and access The network equipment transmits at the maximum rate currently available.
  • the access and mobility management network element sends information indicating the fourth strategy to the access network device.
  • the access and mobility management network element forwards the information received from the session management network element to the access network device. For example, the access and mobility management network element sends the information of the fourth strategy to the access network device.
  • the fourth policy may be carried in the N2 interface message of the access and mobility management network element and the access network device, such as an N2 interface PDU session request (N2PDU session request) message.
  • N2PDU session request N2 interface PDU session request
  • the access network equipment prioritizes integrity protection according to the fourth strategy.
  • the access network device receives the fourth policy, if the rate cannot meet the requirement or in the case that the rate conflicts with integrity protection, the integrity protection is preferred; or the access network device receives After the fourth strategy, when the rate cannot meet the requirement, or when the rate conflicts with integrity protection, integrity protection is selected first, and services are performed at the maximum rate currently provided by the access network device.
  • the access network device may notify the session management network element that the speed reduction process has been performed and the final speed.
  • the foregoing embodiment mainly introduces the situation in which the access network device implements the fourth strategy. It should be understood that the embodiment of the present application is not limited to this. For example, the above-mentioned embodiments can be applied to other strategies, such as scenarios of the first strategy, the second strategy, or the third strategy.
  • the access network device may implement integrity protection and perform transmission at the second rate.
  • the access network device can transmit data with the terminal device at the second rate.
  • the second rate may be the maximum rate currently provided by the access network device indicated in the fourth policy, or the second rate may be any rate lower than the maximum rate currently provided by the access network device, or
  • the second rate may also be a rate indicated by the policy control network element.
  • the access network device may report the second rate to the session management network element. The following will be described in detail with reference to the embodiment shown in FIG. 6.
  • the integrity protection is preferentially selected, so that it can be dynamically adjusted according to the service. Integrity protection strategy to match different business scenarios as much as possible.
  • the fourth strategy may be made and selected by the session management network element, or may be made and selected by the unified data management network element.
  • FIG. 4 is a schematic interaction diagram of a method 400 provided by an embodiment of the present application.
  • the method 400 may include the following steps.
  • the terminal device sends a service request message to the access and mobility management network element.
  • the access and mobility management network element receives the service request message from the terminal device.
  • the service request message sent by the terminal device to the access and mobility management network element is recorded as the first service request message, which is uniformly represented by the first service request message below.
  • step 310 is the same as step 310 in the method 300.
  • step 310 please refer to the above step 310, which will not be repeated here.
  • the access and mobility management network element sends a second service request message to the session management network element.
  • the service request message sent by the access and mobility management network element to the session management network element is recorded as the second service request message, which is uniformly represented by the second service request message below.
  • step 320 is the same as step 320 in method 300.
  • step 320 described above, which will not be repeated here.
  • the session management network element sends a third service request message to the unified data management network element.
  • the service request message sent by the session management network element to the unified data management network element is recorded as the third service request message, which is uniformly represented by the third service request message below.
  • step 330 is the same as step 330 in the method 300.
  • step 330 please refer to the above step 330, which will not be repeated here.
  • the unified data management network element sends a third service response message to the session management network element.
  • the third service response message is a response to the third service request message in step 430.
  • the service response message sent by the unified data management network element to the session management network element is recorded as the third service response message, which is uniformly represented by the third service response message below.
  • the unified data management network element finds the subscription information of the terminal device according to the identifier of the terminal device, such as SUPI, and notifies the session management network element of the subscription information through the third service response message. Or, it can also be understood that the unified data management network element returns a third service response message to the session management network element.
  • the third service response message may be a subscription response message or a communication message (Nudm_SDM_Get_response) between the session management network element and the unified data management network element.
  • the contract information of the terminal device may be pre-stored in the unified data management network element.
  • the subscription information may include a user plane security policy (UP security policy), and the user plane security policy may be used to indicate whether integrity protection needs to be activated.
  • UP security policy user plane security policy
  • the user plane security policy may include the user plane security policy included in the subscription information in the prior art, such as required, not needed, and preferred as described above.
  • the third service response message may include the first indication information.
  • the first indication information may be used to indicate that the integrity protection is preferentially selected when the rate conflicts with the integrity protection.
  • the first indication information may be used to indicate when the capability of the access network device does not support the service required capability of the terminal device, or the first indication information may be used to indicate that the access network device cannot comply with the first
  • the access network device preferentially chooses to enable integrity protection.
  • the first indication information may be used to indicate that integrity protection is preferentially selected when the rate conflicts with integrity protection, and the access network device transmits at the maximum rate currently available.
  • the first indication information may be used to indicate when the capability of the access network device does not support the service required capability of the terminal device, or the first indication information may be used to indicate that the access network device cannot comply with the first
  • the access network device preferentially selects to enable integrity protection, and the access network device transmits at the maximum rate currently available.
  • the unified data management network element may determine whether to send the first indication information according to information such as the service type. For example, for certain services, such as small-capacity voice services, it is of course better to be able to protect integrity. If integrity protection is really not possible, occasional packet loss and tampering will not affect the understanding of the voice content, so for this type of service, you can send The first instruction information.
  • information such as the service type. For example, for certain services, such as small-capacity voice services, it is of course better to be able to protect integrity. If integrity protection is really not possible, occasional packet loss and tampering will not affect the understanding of the voice content, so for this type of service, you can send The first instruction information.
  • the first indication information may also be carried in other messages transmitted between the session management network element and the unified data management network element, or may also be sent through a single signaling.
  • the session management network element determines second indication information according to the subscription information and/or the local policy.
  • the second indication information may be used to indicate that the integrity protection is preferentially selected when the rate conflicts with the integrity protection.
  • the second indication information may be used to indicate that the access network device preferentially selects to enable integrity protection when the access network device cannot execute the user plane security policy at the first rate.
  • the session management network element determines the second indication information, which means that the session management network element indicates to the access network device that if the rate conflicts with the integrity protection, the integrity protection is preferred.
  • the second indication information may be used to indicate that the integrity protection is preferentially selected in the case where the rate conflicts with the integrity protection, and the access network device transmits at the maximum rate currently available.
  • the second indication information can be used to indicate that when the access network device cannot execute the user plane security policy at the first rate, the access network device prefers to enable integrity protection, and the access network device uses the current The maximum transmission rate that can be provided.
  • the session management network element determines the second indication information, which means that the session management network element indicates to the access network device that if the rate conflicts with the integrity protection, the integrity protection is preferred, and the access network is instructed
  • the device transmits at the maximum rate currently available.
  • the second indication information and the first indication information in step 440 may be the same or different, which is not limited. Described below separately.
  • the session management network element obtains the second indication information based on the first indication information obtained from the unified data management network element.
  • the session management network element determines whether to indicate to the access network device whether to instruct the access network device to preferentially select integrity when the rate conflicts with the integrity protection based on the first indication information obtained from the unified data management network element. Protection, or determine whether to indicate to the access network equipment that integrity protection should be preferentially selected when the rate conflicts with integrity protection, and the access network equipment transmits at the maximum rate currently available; or, in other words, the second If the indication information is indicated by the unified data management network element, the session management network element determines whether the second indication information can be indicated to the access network device.
  • the session management network element may generate the second indication information based on the first indication information.
  • the second indication information may include the first indication information or may also be the first indication information, or in other words, the second indication information may be used to indicate that the access network device preferentially turns on when the rate conflicts with integrity protection. Integrity protection, or the second indication information can be used to indicate that in the case of a rate conflict with integrity protection, the access network device preferentially selects to enable integrity protection, and the access network device transmits at the maximum rate currently available.
  • the session management network element may determine whether to indicate the second indication information based on the service type and/or the capability of the access network device. Alternatively, the session management network element may also determine to indicate the second indication information to the access network device directly according to the first indication information.
  • the session management network element may generate a third security policy according to the subscription information of the terminal device obtained from the unified data management network element, and the third security policy may include the user plane security policy in step 440, such as required, not need, or preferred.
  • the session management network element obtains the second indication information according to other information.
  • the session management network element determines whether the second indication information can be indicated to the access network device according to other information of the terminal device; or, in other words, the second indication information is indicated by the session management network element, namely The session management network element judges whether the access network device should preferentially select to enable integrity protection when the rate conflicts with the integrity protection, and if so, the session management network element indicates the second indication information.
  • the session management network element can also generate the second indication information based on one or more comprehensive judgments of other information, such as local policy, obtained slice-related information, supported service types, etc., or in other words, determine the speed and integrity In the case of a sexual protection conflict, whether the access network device should give priority to turning on integrity protection.
  • the security requirements of the service type can be obtained from the contract information; it can also interact with other network elements, such as policy control network elements, application service network elements, and so on.
  • the session management network element may also generate a fourth security policy based on other information, such as one or more comprehensive judgments of local policy, obtained slice related information, supported service types, and other information.
  • the fourth security policy may include, for example, required, not needed, or preferred. Among them, the security requirements of the service type can be obtained from the contract information; it can also interact with other network elements, such as policy control network elements, application service network elements, and so on.
  • the second indication information and the first indication information may be the same or different, which is not limited in this application.
  • FIG. 4 only shows the case where the second indication information is determined, that is, the case where the access network device prefers integrity protection, and the embodiment of the present application is not limited to this.
  • the method 400 may further include the following steps.
  • the session management network element sends a second service response message to the access and mobility management network element.
  • the second service response message is a response to the second service request message in step 420.
  • the service response message sent by the session management network element to the access and mobility management network element is recorded as the second service response message, which is uniformly represented by the second service response message below.
  • the second service response message may be a PDU session creation session management context service response.
  • step 460 can also be understood as that the session management network element returns a PDU session creation session management context service response to the access and mobility management network element.
  • the second service response message sent by the session management network element to the access and mobility management network element carries the second indication information in step 450.
  • the second service response message may include the second indication information.
  • the indication information is used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, or the second indication information is used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, and access The network equipment transmits at the maximum rate currently available.
  • the access and mobility management network element sends information indicating the second indication information to the access network device.
  • the access and mobility management network element forwards the information received from the session management network element to the access network device.
  • the access and mobility management network element sends the second instruction information and the security policy to the access network device, and the security policy is the third security policy or the fourth security policy.
  • the second indication information and the security policy may be carried in the N2 interface message of the access and mobility management network element and the access network device, such as an N2 interface PDU session request (N2PDU session request) message.
  • N2PDU session request N2 interface PDU session request
  • the access network device preferentially implements integrity protection according to the second instruction information.
  • the access network device receives the second indication information, if the rate cannot meet the requirement or in the case that the rate conflicts with the integrity protection, the integrity protection is preferred; or the access network device receives After the second indication information, when the rate cannot meet the requirement or when the rate conflicts with the integrity protection, the integrity protection is selected first, and the service is performed at the maximum rate currently provided by the access network device.
  • the access network device may notify the session management network element that the speed reduction process has been performed and the final speed.
  • the access network device in the case of a conflict between the rate and the integrity protection, can implement integrity protection and transmit at the second rate, that is, the access network device can perform the transmission at the second rate.
  • the second rate may be the maximum rate currently provided by the access network device indicated in the second indication information, or the second rate may also be any rate lower than the maximum rate currently provided by the access network device, or,
  • the second rate may also be a rate indicated by the policy control network element.
  • the access network device may report the second rate to the session management network element. The following will be described in detail with reference to the embodiment shown in FIG. 6.
  • the instruction information when the capacity of the access network device does not meet the service capability requirements, that is, in the case of a conflict between the rate and the integrity protection, the integrity protection is preferred, so that the integrity can be adjusted dynamically according to the service.
  • the instruction information may be the second instruction information that is made by the session management network element to make a decision; or, the instruction information may also be the first instruction information that is made and generated by the unified data management network element.
  • FIG. 5 is a schematic interaction diagram of a method 500 provided by an embodiment of the present application.
  • the method 500 may include the following steps.
  • the terminal device sends a service request message to the access and mobility management network element.
  • the access and mobility management network element receives the service request message from the terminal device.
  • the terminal device initiates a service request message to the access and mobility management network element.
  • the service request message may be used to request the establishment of a connection between the terminal device and the service server of the data network, and the connection with the service server of the data network requested by the service request message may be used to transmit data.
  • the data may be, for example, general data, small data, data corresponding to specific services, etc., which is not limited in this application.
  • the service request message sent by the terminal device to the access and mobility management network element is recorded as the first service request message, which is uniformly represented by the first service request message below.
  • the terminal device may send the first service request message to the access and mobility management network element via the access network device.
  • the first service request message is a service request message or a PDU session establishment request message.
  • the first service request message may carry slices or specific service related information, such as service type, S-NSSAI, etc.
  • the S-NSSAI may indicate the slice information requested by the terminal device.
  • the first service request message may carry DNN to indicate the name of the data network that the terminal device requests to access.
  • the first service request message may include third indication information.
  • the third indication information may be used to indicate that the integrity protection is preferentially selected when the rate conflicts with the integrity protection.
  • the third indication information may be used to indicate that when the capability of the access network device does not support the service requirement capability of the terminal device, the access network device preferentially selects to enable integrity protection.
  • the third indication information may be used to indicate that integrity protection is preferentially selected in the case where the rate conflicts with integrity protection, and the access network device transmits at the maximum rate currently available.
  • the third indication information can be used to indicate that when the access network device cannot execute the user plane security policy at the first rate, the access network device prefers to turn on integrity protection, and the access network device uses the current The maximum transmission rate that can be provided.
  • the terminal device may determine whether to send the third instruction information according to information such as the type of the service to be transmitted. For example, for certain services, such as small-capacity voice services, it is of course better to be able to protect integrity. If integrity protection is really not possible, occasional packet loss and tampering will not affect the understanding of the voice content, so for this type of service, you can send The third instruction information.
  • the third indication information sent by the terminal device may be session granularity, that is, indication information for different data networks (DNs) or applications.
  • the indication information for different DNs or applications can be pre-configured, such as specified in the protocol; or the terminal device itself can be configured; or it can be obtained from the core network during the registration process, etc., which is not limited.
  • this indication (that is, the third indication information) can be introduced in a user routing selection policy (UE routing selection policy, URSP).
  • UE routing selection policy UE routing selection policy
  • the relationship between the application and the PDU session attribute is defined through the URSP. For certain types of applications, if the rate does not meet the requirements, the session can not be rejected, and the maximum rate that can currently be transmitted is sufficient.
  • the third indication information may also be carried in other messages transmitted between the terminal device and the access and mobility management network element, or may also be sent through a single signaling.
  • the access and mobility management network element sends a second service request message to the session management network element.
  • the service request message sent by the access and mobility management network element to the session management network element is recorded as the second service request message, which is uniformly represented by the second service request message below. It can also be understood that the access and mobility management network element invokes the session creation session management context service provided by the session management network element.
  • step 320 is similar to step 320 in the method 300.
  • step 320 please refer to the above step 320, which will not be repeated here.
  • the second service request message includes third indication information, that is, the third indication information in step 510.
  • the session management network element determines fourth indication information according to the second service request message.
  • the session management network element determines, according to the received second service request message, whether to preferentially select integrity protection when the rate conflicts with integrity protection.
  • the fourth indication information may be used to indicate that the integrity protection is preferentially selected when the rate conflicts with the integrity protection.
  • the fourth indication information may be used to indicate that when the capability of the access network device does not support the service required capability of the terminal device, the access network device preferentially selects to enable integrity protection.
  • the session management network element determines the fourth indication information, which means that the session management network element indicates to the access network device that if the rate conflicts with the integrity protection, the integrity protection is preferentially selected.
  • the fourth indication information may be used to indicate that integrity protection is preferentially selected in the case where the rate conflicts with integrity protection, and the access network device transmits at the maximum rate currently available.
  • the fourth indication information can be used to indicate that when the capability of the access network device does not support the service required capability of the terminal device, the access network device prefers to enable integrity protection, and the access network device can currently provide The maximum rate of transmission.
  • the session management network element determines the fourth indication information, which means that the session management network element indicates to the access network device that if the rate conflicts with the integrity protection, the integrity protection is preferred, and the access network is instructed The device transmits at the maximum rate currently available.
  • the fourth indication information and the third indication information in step 510 may be the same or different, which is not limited. Described below separately.
  • the session management network element obtains the fourth indication information based on the obtained third indication information.
  • the session management network element determines whether to instruct the access network device to preferentially select integrity protection when the rate conflicts with the integrity protection according to the third indication information obtained from the terminal device, or Determine whether to instruct the access network device to preferentially select integrity protection when the rate conflicts with integrity protection, and the access network device transmits at the maximum rate currently available; or, in other words, the fourth indication information is As indicated by the terminal device, the session management network element determines whether the fourth indication information can be indicated to the access network device.
  • the session management network element may generate fourth indication information based on the third indication information.
  • the fourth indication information may include the third indication information or may also be the third indication information, or in other words, the fourth indication information may be used to indicate that in the case of a rate conflict with integrity protection, the access network device preferentially turns on Integrity protection, or the fourth indication information may be used to indicate that in the case of a rate conflict with integrity protection, the access network device preferentially selects to turn on integrity protection, and the access network device transmits at the maximum rate currently available.
  • the session management network element may determine whether to indicate the fourth indication information based on the service type and/or the capability of the access network device. Alternatively, the session management network element may directly determine to indicate the fourth indication information to the access network device according to the third indication information.
  • the session management network element obtains the fourth indication information according to other information.
  • the session management network element determines whether the fourth indication information can be indicated to the access network device according to other information of the terminal device; or, in other words, the fourth indication information is indicated by the session management network element, namely The session management network element determines whether the access network device should preferentially select to enable integrity protection when the rate conflicts with the integrity protection, and if so, the session management network element indicates the fourth indication information.
  • the session management network element may also generate the fourth indication information based on one or more comprehensive judgments of other information, such as local policy, obtained slice-related information, supported service types, etc., or in other words, determine whether the rate and integrity In the case of a sexual protection conflict, whether the access network device should give priority to turning on integrity protection.
  • the security requirements of the service type can be obtained from the contract information; it can also interact with other network elements, such as policy control network elements, application service network elements, and so on.
  • the fourth indication information and the third indication information may be the same or different, which is not limited in this application.
  • the session management network element may generate a security policy, and the security policy may be required, not needed, or preferred.
  • FIG. 5 only shows the case where the fourth indication information is determined, that is, the case where the access network device prefers integrity protection, and the embodiment of the present application is not limited to this.
  • the method 500 may further include the following steps.
  • the session management network element sends a second service response message to the access and mobility management network element.
  • the second service response message is a response to the second service request message in step 520.
  • the service response message sent by the session management network element to the access and mobility management network element is recorded as the second service response message, which is uniformly represented by the second service response message below.
  • the second service response message may be a PDU session creation session management context service response.
  • step 540 can also be understood as that the session management network element returns a PDU session creation session management context service response to the access and mobility management network element.
  • the second service response message sent by the session management network element to the access and mobility management network element carries the fourth indication information in step 530.
  • the second service response message may include the fourth indication information.
  • the indication information is used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, or the fourth indication information is used to indicate that integrity protection is preferred when the rate conflicts with integrity protection, and access The network equipment transmits at the maximum rate currently available.
  • the access and mobility management network element sends information indicating fourth indication information to the access network device.
  • the access and mobility management network element forwards the information received from the session management network element to the access network device. For example, the access and mobility management network element sends the fourth instruction information and the security policy to the access network device, and the security policy is the security policy generated in step 530.
  • the fourth indication information and security policy may be carried in the N2 interface message of the access and mobility management network element and the access network device, such as an N2 interface PDU session request (N2PDU session request) message.
  • N2PDU session request N2 interface PDU session request
  • the access network device prioritizes integrity protection according to the fourth instruction information.
  • the access network device receives the fourth indication information, in the case that the rate cannot meet the requirement or in the case that the rate conflicts with the integrity protection, the integrity protection is preferred; or the access network device receives After the fourth indication information, in the case that the rate cannot meet the requirement or the rate conflicts with the integrity protection, the integrity protection is selected first, and the service is performed at the maximum rate currently provided by the access network device.
  • the access network device may also determine whether to perform speed reduction processing according to its own capabilities.
  • the access network device may notify the session management network element that the speed reduction process has been performed and the final speed.
  • the access network device in the case of a conflict between the rate and the integrity protection, can implement integrity protection and transmit at the second rate, that is, the access network device can perform the transmission at the second rate.
  • the second rate may be the maximum rate currently provided by the access network device indicated in the fourth indication information, or the second rate may also be any rate lower than the maximum rate currently provided by the access network device, or,
  • the second rate may also be a rate indicated by the policy control network element.
  • the access network device may report the second rate to the session management network element. The following will be described in detail with reference to the embodiment shown in FIG. 6.
  • the instruction information when the access network equipment cannot meet the service capability requirements, that is, when the rate conflicts with integrity protection, or in other words, the access network equipment cannot perform at the first rate.
  • integrity protection is preferred, so that the integrity protection strategy can be dynamically adjusted according to the business to match different business scenarios as much as possible.
  • the instruction information may be made and generated by the terminal device.
  • the following describes the transmission rate when the access network device and the terminal device transmit data, that is, the second rate, with reference to FIG. 6.
  • FIG. 6 is a schematic interaction diagram of a method 600 provided by an embodiment of the present application.
  • the method 600 may include the following steps.
  • the terminal device sends a service request message to the access and mobility management network element.
  • the access and mobility management network element receives the service request message from the terminal device.
  • the service request message sent by the terminal device to the access and mobility management network element is recorded as the first service request message, which is uniformly represented by the first service request message below.
  • step 310 in method 300 For this step, reference may be made to step 310 in method 300, step 410 in method 400, or step 510 in method 500, which will not be repeated here.
  • the access and mobility management network element sends a second service request message to the session management network element.
  • the service request message sent by the access and mobility management network element to the session management network element is recorded as the second service request message, which is uniformly represented by the second service request message below.
  • step 320 in the method 300 reference may be made to step 320 in the method 300, step 420 in the method 400, or step 520 in the method 500, which will not be repeated here.
  • the session management network element sends a third service request message to the unified data management network element.
  • the service request message sent by the session management network element to the unified data management network element is recorded as the third service request message, which is uniformly represented by the third service request message below.
  • step 330 in the method 300 or step 430 in the method 400 which will not be repeated here.
  • the unified data management network element sends a third service response message to the session management network element.
  • step 340 in the method 300 or step 440 in the method 400 which will not be repeated here.
  • the session management network element determines whether the access network device should preferentially select integrity protection according to the subscription information and/or the local policy.
  • step 350 the session management network element determines to implement the fourth strategy according to the subscription information and/or the local strategy, which will not be repeated here.
  • this step may refer to step 450 in the above method 400, that is, the session management network element determines the second indication information according to the subscription information and/or the local policy, which will not be repeated here.
  • this step may refer to step 530 in the above method 500, that is, the session management network element determines the fourth indication information according to the second service request message, which will not be repeated here.
  • the policy control network element may determine the second rate, that is, the transmission rate when the access network device implements the integrity protection in the case that the rate conflicts with the integrity protection. For example, the following steps 601 to 603 can be used to determine the second rate.
  • the session management network element sends fifth indication information to the policy control network element.
  • the fifth indication information may be used to indicate that the access network device will perform integrity protection when the rate conflicts with integrity protection.
  • the fifth indication information may be carried in a communication message (Npcf_SMPolicyControl_Create_request) between the session management network element and the policy control network element.
  • the fifth indication information may include the maximum rate that the access network device can currently provide.
  • the policy control network element determines the second rate.
  • the policy control network element determines the final rate according to the fifth instruction information, and the final rate may be the rate of the service data flow.
  • the policy control network element sends sixth indication information to the session management network element.
  • the sixth indication information may be a response to the fifth indication information. It can also be understood that the policy control network element returns the sixth indication information to the session management network element.
  • the sixth indication information may indicate the final rate information in step 602.
  • the sixth indication information may be carried in a communication message (Npcf_SMPolicyControl_Create_response) between the session management network element and the policy control network element.
  • the session management network element may process the final rate indicated by the sixth indication information to obtain a quality of service (QoS) flow (QoS flow).
  • QoS quality of service
  • the session management network element can determine the final QoS flow corresponding to the data transmitted by the terminal device and the access network device.
  • the session management network element sends a second service response message to the access and mobility management network element.
  • step 360 in the method 300
  • step 460 in the method 400 or step 540 in the method 500, which will not be repeated here.
  • the second service response message may also include QoS flow information.
  • the access and mobility management network element sends to the access network device information instructing the access network device to preferentially select integrity protection.
  • step 370 the access and mobility management network element sends the information indicating the fourth strategy to the access network device, which will not be repeated here.
  • this step may refer to step 470 in the above method 400, that is, the access and mobility management network element sends the information indicating the second indication information to the access network device, which will not be repeated here.
  • this step may refer to step 550 in the above method 500, that is, the access and mobility management network element sends the information indicating the fourth indication information to the access network device, which will not be repeated here.
  • the information instructing the access network device to preferentially select integrity protection may also include QoS flow information.
  • the access network device preferentially selects integrity protection information according to the instruction to the access network device, and performs integrity protection first.
  • step 380 the access network device preferentially implements integrity protection according to the fourth policy, which will not be repeated here.
  • this step may refer to step 480 in the above method 400, that is, the access network device preferentially implements integrity protection according to the second instruction information, which will not be repeated here.
  • this step can refer to step 560 in the above method 500, that is, the access network device preferentially implements integrity protection according to the fourth instruction information, which will not be repeated here.
  • the information instructing the access network device to preferentially select integrity protection may also include QoS flow information, and the access network device may determine whether to reduce the speed and the second rate based on the QoS flow information.
  • the second rate is less than or equal to the maximum rate currently provided by the access network device.
  • the access network device may also determine whether it needs to perform speed reduction processing according to its own capabilities.
  • the access network device may notify the session management network element that the speed reduction process has been performed and the final speed.
  • the access network device can also determine the final transmission rate (that is, the second rate) according to the instruction of the policy control network element.
  • FIG. 7 is a schematic interaction diagram of a method 700 provided by an embodiment of the present application.
  • the method 700 may include the following steps.
  • the terminal device sends a service request message to the access and mobility management network element.
  • the access and mobility management network element receives the service request message from the terminal device.
  • the service request message sent by the terminal device to the access and mobility management network element is recorded as the first service request message, which is uniformly represented by the first service request message below.
  • step 310 in the above method 300 or step 410 in the method 400, which will not be repeated here.
  • the access and mobility management network element sends a second service request message to the session management network element.
  • the service request message sent by the access and mobility management network element to the session management network element is recorded as the second service request message, which is uniformly represented by the second service request message below.
  • step 320 in the method 300 or step 420 in the method 400 which will not be repeated here.
  • the session management network element Based on the second service request message, the session management network element performs processing.
  • the session management network element may determine a security algorithm based on the second service request message; another example, the session management network element generates an encryption key and an integrity protection key based on the second service request message; another example, the session management network Based on the second service request message, the element generates a security policy, and so on.
  • This step can be implemented according to existing standards, which are not limited in the embodiment of the present application.
  • the session management network element sends a second service response message to the access and mobility management network element.
  • the second service response message is a response to the second service request message in step 720.
  • the service response message sent by the session management network element to the access and mobility management network element is recorded as the second service response message, which is uniformly represented by the second service response message below.
  • the second service response message may be a PDU session creation session management context service response.
  • step 740 can also be understood as that the session management network element returns a PDU session creation session management context service response to the access and mobility management network element.
  • the second service response message sent by the session management network element to the access and mobility management network element may carry the information determined by the session management network element in step 730, such as a security policy and/or a security algorithm.
  • the access and mobility management network element sends a request message to the access network device.
  • the access and mobility management network element forwards the information received from the session management network element to the access network device.
  • the request message may be an N2 interface message between the access and mobility management network element and the access network device, such as an N2 interface PDU session request (N2PDU session request) message.
  • N2PDU session request N2PDU session request
  • the access network device in the case where the rate conflicts with the integrity protection, can decide by itself whether to preferentially select the integrity protection.
  • the method 700 may also include the following steps.
  • the access network device determines whether speed reduction processing can be performed.
  • the access network device finds that the rate cannot meet the requirement or that the rate conflicts with integrity protection, then the access network device can determine whether speed reduction can be performed to implement integrity protection.
  • the access network device can determine whether it can perform speed reduction processing based on its own capabilities.
  • a possible implementation method When the access network device determines that the rate conflicts with the integrity protection, the integrity protection is preferred, and the speed reduction process is performed by itself, and the access network device can notify the session management network element to reduce the speed process result.
  • the access network device when the access network device determines that the rate conflicts with the integrity protection, it preferentially selects the integrity protection, and requests the session management network element whether the speed can be reduced. In other words, the access network device will perform the speed reduction process after obtaining the approval of the session management network element.
  • the method 700 may further include step 770 and step 780.
  • the access network device sends a message requesting speed reduction to the session management network element.
  • the speed reduction request message is used to request the session management network element, whether the access network device can perform speed reduction processing.
  • the message requesting the speed reduction can be implemented by the forwarding of the access and mobility management network element. That is, the access network device sends the message requesting speed reduction to the access and mobility management network element, and the access and mobility management network element forwards the message requesting speed reduction to the session management network element.
  • the session management network element sends a message indicating speed reduction to the access network device.
  • the message indicating the speed reduction can be implemented by the forwarding of the access and mobility management network element. That is, the session management network element sends the message indicating the speed reduction to the access and mobility management network element, and the access and mobility management network element forwards the message indicating the speed reduction to the access network device.
  • the message indicating the speed reduction is used to indicate that the access network device can or cannot perform speed reduction processing.
  • the access network device can implement integrity protection and perform speed reduction processing.
  • the access network device when the message indicating speed reduction is used to indicate that the access network device cannot perform speed reduction processing, the access network device will not implement integrity protection, and will not perform speed reduction processing.
  • the access network device may transmit data with the terminal device at the second rate after the speed reduction processing.
  • the second rate may be the second rate obtained by the method 600, or may be determined by the access network device itself, or may be determined by the access network device itself and approved by the session management network element.
  • the second rate may be less than or equal to the maximum rate currently provided by the access network device.
  • the access network device may report the second rate to the session management network element.
  • integrity protection can be preferentially selected by self-determination, and the session management network element can be notified, so that the integrity protection strategy can be dynamically adjusted according to the business to match different business scenarios as much as possible.
  • the size of the sequence number of each process does not mean the order of execution.
  • the execution order of each process should be determined by its function and internal logic, and should not be implemented in the embodiments of this application.
  • the process constitutes any limitation.
  • the methods and operations implemented by the terminal side can also be implemented by components (such as chips or circuits) that can be used for terminal-side devices
  • the methods and operations implemented by the network side can also be implemented It is implemented by components (such as chips or circuits) that can be used in network side devices.
  • each network element such as a transmitting end device or a receiving end device, includes hardware structures and/or software modules corresponding to each function in order to realize the above functions.
  • the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed by hardware or computer software-driven hardware depends on the specific application and design constraint conditions of the technical solution. Professionals and technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered beyond the scope of this application.
  • each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module.
  • the above-mentioned integrated modules can be implemented in the form of hardware or software functional modules. It should be noted that the division of modules in the embodiments of the present application is illustrative, and is only a logical function division, and there may be other division methods in actual implementation. The following is an example of dividing each functional module corresponding to each function
  • FIG. 8 is a schematic block diagram of a secure conversation apparatus 800 provided by an embodiment of the present application.
  • the communication device 800 may include: a transceiver unit 810 and a processing unit 820.
  • the secure session device 800 may be the access network device in the above method embodiment, or may be a chip for implementing the function of the access network device in the above method embodiment.
  • the transceiver unit 810 is configured to: receive a session request message sent by a session management network element, the session request message carries the user plane security policy of the terminal device and the first rate information; the processing unit 820 is configured to: When the secure conversation device 800 cannot execute the user plane security policy at the first rate, the integrity protection is activated at the second rate, where the second rate is lower than the first rate.
  • the second rate is less than or equal to the maximum transmission rate currently supported by the secure session device 800.
  • the processing unit 820 is specifically configured to: based on the user plane security policy, activate the integrity protection at the second rate.
  • the user plane security policy is determined by the session management network element or the unified data management network element.
  • the session request message includes indication information; the processing unit 820 is specifically configured to: based on the indication information, activate integrity protection at the second rate.
  • the processing unit 820 is specifically configured to: in a case where it is determined that the session meets a preset condition, activate the integrity protection at the second rate.
  • the transceiver unit 810 is further configured to receive rate information from the policy control network element, where the rate information is used to indicate the second rate.
  • the transceiving unit 810 is further configured to send information of the second rate to the session management network element.
  • the secure conversation apparatus 800 may correspond to the access network equipment in the methods 200 to 700 according to the embodiments of the present application, and the secure conversation apparatus 800 may include methods for executing the methods 200 to 7 in FIG. 2 Unit of the method executed by the access network device in 700.
  • each unit in the secure conversation device 800 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG.
  • the secure session device 800 may be the session management network element in the above method embodiment, or a chip for implementing the function of the session management network element in the above method embodiment.
  • the processing unit 820 is configured to determine a user plane security policy of the terminal device, and the user plane security policy is used to indicate: when the access network device cannot execute the user plane security policy at the first rate, The access network device activates integrity protection at a second rate, where the second rate is lower than the first rate; the transceiver unit 810 is configured to send a user plane security policy to the access network device.
  • the transceiving unit 810 is further configured to: obtain subscription information of the terminal device; the processing unit 820 is specifically configured to determine the user plane security policy of the terminal device based on the subscription information of the terminal device.
  • the processing unit 820 is specifically configured to determine the user plane security policy of the terminal device according to the session request message of the terminal device.
  • the processing unit 820 is further configured to: receive rate information provided by the policy control network element; the transceiving unit 810 is further configured to: send information indicating the second rate to the access network device based on the rate information.
  • the transceiver unit 810 is further configured to: receive the second rate information sent by the access network device.
  • the transceiver unit 810 is configured to: receive a session creation session management context service request initiated by an access and mobility management network element; the transceiver unit 810 is also configured to: create a session management context service request based on the session, and send The access and mobility management network element returns a session creation session management context service response.
  • the session creation session management context service response includes indication information, which is used to indicate that the access network device cannot execute the user plane security policy at the first rate Next, the access network device activates integrity protection at a second rate, where the second rate is lower than the first rate.
  • the session creation session management context service request includes notification information, and the notification information is used to notify that the access network device activates integrity at the second rate when the access network device cannot execute the user plane security policy at the first rate. Protection;
  • the transceiver unit 810 is specifically configured to: determine the indication information based on the notification information.
  • the session creation session management context service request includes information of the service type of the terminal device; the processing unit 820 is configured to determine the indication information based on the information of the service type.
  • the transceiver unit 810 is further configured to: receive rate information provided by the policy control network element; the processing unit 820 is further configured to: based on the rate information, determine that the access network device cannot execute the user plane security policy at the first rate Next, the access network device activates integrity protection at the second rate.
  • the transceiver unit 810 is further configured to: receive the second rate information sent by the access network device.
  • the secure session device 800 may correspond to the session management network element in the methods 200 to 700 according to the embodiments of the present application, and the secure session device 800 may include methods for executing the methods 200 to 7 in FIG. 2 Unit of the method performed by the session management network element in 700.
  • each unit in the secure conversation device 800 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG.
  • the secure conversation device 800 may be the UE in the above method embodiment, or may be a chip for implementing the function of the UE in the above method embodiment.
  • the processing unit 820 is configured to: determine indication information, and the indication information is used to indicate: in the case that the access network device cannot execute the user plane security policy at the first rate, the access network device performs the second rate Integrity protection is activated, where the second rate is lower than the first rate; the transceiver unit 810 is configured to send indication information to the access and mobility management network element.
  • the secure session device 800 may correspond to the UE in the methods 200 to 700 according to the embodiments of the present application, and the secure session device 800 may include methods for executing the method 200 in FIG. 2 to the method 700 in FIG. Unit of the method performed by the UE.
  • each unit in the secure conversation device 800 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG. The corresponding process of the method 600 in FIG. 6 or the method 700 in FIG. 7.
  • the secure conversation device 800 may be the access and mobility management network element in the above method embodiment, or it may be used to implement the access and mobility management network element in the above method embodiment.
  • the function of the chip may be the access and mobility management network element in the above method embodiment, or it may be used to implement the access and mobility management network element in the above method embodiment. The function of the chip.
  • the secure session device 800 may correspond to the access and mobility management network elements in the methods 200 to 700 according to the embodiments of the present application, and the secure session device 800 may include methods for executing the methods 200 to 7 in FIG. 2
  • each unit in the secure conversation device 800 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG.
  • the secure conversation device 800 may be the unified data management network element in the above method embodiment, or a chip for implementing the function of the unified data management network element in the above method embodiment. .
  • the secure conversation device 800 may correspond to the unified data management network element in the methods 200 to 700 according to the embodiments of the present application, and the secure conversation device 800 may include methods for executing methods 200 to 7 in FIG. 2 The unit of the method executed by the unified data management network element in the method 700.
  • each unit in the secure conversation device 800 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG. The corresponding process of the method 600 in FIG. 6 or the method 700 in FIG. 7.
  • the secure conversation device 800 may be the policy control network element in the above method embodiment, or a chip for implementing the function of the policy control network element in the above method embodiment.
  • the secure conversation device 800 may correspond to the policy control network element in the method 600 according to the embodiment of the present application, and the secure conversation device 800 may include a network element for executing the policy control network element in the method 600 in FIG. Method unit.
  • each unit in the secure conversation device 800 and other operations and/or functions described above are used to implement the corresponding process of the method 600 in FIG. 6.
  • transceiving unit in the secure conversation device 800 may correspond to the transceiver 910 in the secure conversation device 900 shown in FIG. 9, and the processing unit 820 in the secure conversation device 800 may correspond to that shown in FIG. 9 The transceiver 920 in the secure conversation device 900.
  • the secure conversation device 800 when the secure conversation device 800 is a chip, the chip includes a transceiver unit and a processing unit.
  • the transceiver unit may be an input/output circuit or a communication interface;
  • the processing unit may be a processor, microprocessor, or integrated circuit integrated on the chip.
  • FIG. 9 is a schematic block diagram of a secure conversation device 900 according to an embodiment of the present application.
  • the secure conversation device 900 includes a processor 910 and a transceiver 920.
  • the processor 910 is coupled with the memory, and is configured to execute instructions stored in the memory to control the transceiver 920 to send signals and/or receive signals.
  • the secure conversation device 900 further includes a memory 930 for storing instructions.
  • processor 910 and the memory 930 may be combined into one processing device, and the processor 910 is configured to execute the program code stored in the memory 930 to implement the foregoing functions.
  • the memory 930 may also be integrated in the processor 910 or independent of the processor 910.
  • the transceiver 920 may include a receiver (or called a receiver) and a transmitter (or called a transmitter).
  • the transceiver may further include an antenna, and the number of antennas may be one or more.
  • the secure conversation device 900 may be the access network device in the above method embodiment, or may be a chip for implementing the function of the access network device in the above method embodiment.
  • the secure conversation device 900 may correspond to the access network equipment in the methods 200 to 700 according to the embodiments of the present application, and the secure conversation device 900 may include methods for executing the methods 200 to 7 in FIG. 2 Unit of the method executed by the access network device in 700.
  • each unit in the secure conversation device 900 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG.
  • the secure session device 900 may be the session management network element in the above method embodiment, or may be a chip for realizing the function of the session management network element in the above method embodiment. It should be understood that the specific process for each unit to execute the foregoing corresponding steps has been described in detail in the foregoing method embodiment, and is not repeated here for brevity.
  • the secure session device 900 may be the session management network element in the above method embodiment, or may be a chip for realizing the function of the session management network element in the above method embodiment.
  • the secure session device 900 may correspond to the session management network element in the methods 200 to 700 according to the embodiments of the present application, and the secure session device 900 may include methods for executing the methods 200 to 7 in FIG. 2 Unit of the method performed by the session management network element in 700.
  • each unit in the secure conversation device 800 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG.
  • the secure conversation device 900 may be the access and mobility management network element in the above method embodiment, or it may be used to implement the access and mobility management network element in the above method embodiment.
  • the function of the chip may be the access and mobility management network element in the above method embodiment, or it may be used to implement the access and mobility management network element in the above method embodiment. The function of the chip.
  • the secure conversation device 900 may correspond to the access and mobility management network elements in the methods 200 to 700 according to the embodiments of the present application, and the secure conversation device 900 may include methods for executing the methods 200 to 7 in FIG. 2
  • each unit in the secure conversation device 900 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG.
  • the secure conversation device 900 may be the UE in the above method embodiment, or may be a chip for implementing the function of the UE in the above method embodiment.
  • the secure conversation device 900 may correspond to the UE in the methods 200 to 700 according to the embodiments of the present application, and the secure conversation device 900 may include methods for executing the method 200 in FIG. 2 to the method 700 in FIG. Unit of the method performed by the UE.
  • each unit in the secure conversation device 900 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG.
  • the secure conversation device 900 may be the unified data management network element in the above method embodiment, or a chip for implementing the function of the unified data management network element in the above method embodiment. .
  • the secure session device 900 may correspond to the unified data management network element in the methods 200 to 700 according to the embodiments of the present application, and the secure session device 900 may include methods for executing methods 200 to 7 in FIG. 2 The unit of the method executed by the unified data management network element in the method 700.
  • each unit in the secure conversation device 900 and other operations and/or functions described above are used to implement the method 200 in FIG. 2, the method 300 in FIG. 3, the method 400 in FIG. 4, the method 500 in FIG. The corresponding process of the method 600 in FIG. 6 or the method 700 in FIG. 7.
  • the secure conversation device 900 may be the policy control network element in the above method embodiment, or a chip for implementing the function of the policy control network element in the above method embodiment.
  • the secure conversation device 900 may correspond to the policy control network element in the method 600 according to the embodiment of the present application, and the secure conversation device 900 may include a network element for executing the policy control network element in the method 600 in FIG. Method unit.
  • each unit in the secure conversation device 900 and other operations and/or functions described above are used to implement the corresponding process of the method 600 in FIG. 6.
  • the chip When the secure conversation device 900 is a chip, the chip includes a transceiver unit and a processing unit.
  • the transceiver unit may be an input/output circuit or a communication interface;
  • the processing unit may be a processor or microprocessor or integrated circuit integrated on the chip.
  • the embodiment of the present application also provides a processing device, including a processor and an interface.
  • the processor may be used to execute the method in the foregoing method embodiment.
  • the processing device may be a chip.
  • the processing device may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), or a system on chip (SoC), or It is a central processor unit (CPU), it can also be a network processor (NP), it can also be a digital signal processing circuit (digital signal processor, DSP), or it can be a microcontroller (microcontroller unit). , MCU), it can also be a programmable logic device (PLD) or other integrated chips.
  • FPGA field programmable gate array
  • ASIC application specific integrated circuit
  • SoC system on chip
  • CPU central processor unit
  • NP network processor
  • DSP digital signal processing circuit
  • microcontroller unit microcontroller unit
  • MCU programmable logic device
  • PLD programmable logic device
  • the steps of the above method can be completed by hardware integrated logic circuits in the processor or instructions in the form of software.
  • the steps of the method disclosed in the embodiments of the present application may be directly embodied as being executed and completed by a hardware processor, or executed and completed by a combination of hardware and software modules in the processor.
  • the software module can be located in a mature storage medium in the field such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, registers.
  • the storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
  • the processor in the embodiment of the present application may be an integrated circuit chip with signal processing capability.
  • the steps of the foregoing method embodiments can be completed by hardware integrated logic circuits in the processor or instructions in the form of software.
  • the above-mentioned processor may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components .
  • DSP digital signal processor
  • ASIC application specific integrated circuit
  • FPGA field programmable gate array
  • the methods, steps, and logical block diagrams disclosed in the embodiments of the present application can be implemented or executed.
  • the general-purpose processor may be a microprocessor or the processor may also be any conventional processor or the like.
  • the steps of the method disclosed in the embodiments of the present application may be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor.
  • the software module can be located in a mature storage medium in the field such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, registers.
  • the storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
  • the memory in the embodiment of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memory.
  • the non-volatile memory can be read-only memory (ROM), programmable read-only memory (programmable ROM, PROM), erasable programmable read-only memory (erasable PROM, EPROM), and electronic Erase programmable read-only memory (electrically EPROM, EEPROM) or flash memory.
  • the volatile memory may be random access memory (RAM), which is used as an external cache.
  • RAM random access memory
  • static random access memory static random access memory
  • dynamic RAM dynamic random access memory
  • DRAM dynamic random access memory
  • SDRAM synchronous dynamic random access memory
  • double data rate synchronous dynamic random access memory double data rate SDRAM, DDR SDRAM
  • enhanced synchronous dynamic random access memory enhanced SDRAM, ESDRAM
  • serial link DRAM SLDRAM
  • direct rambus RAM direct rambus RAM
  • the present application also provides a computer program product.
  • the computer program product includes: computer program code, which when the computer program code runs on a computer, causes the computer to execute the steps shown in FIGS. 2 to 7 The method of any one of the embodiments is shown.
  • the present application also provides a computer-readable medium that stores program code, and when the program code runs on a computer, the computer executes the steps shown in FIGS. 2 to 7 The method of any one of the embodiments is shown.
  • the present application also provides a system, which includes the aforementioned session management network element, access network equipment, and UE.
  • the present application also provides a system, which includes the aforementioned session management network element, access and mobility management network element, access network equipment, unified data management network element, and UE.
  • the computer program product includes one or more computer instructions.
  • the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.
  • the computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website, computer, server, or data center.
  • the computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or a data center integrated with one or more available media.
  • the usable medium may be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a high-density digital video disc (digital video disc, DVD)), or a semiconductor medium (for example, a solid state disk (solid state disc, SSD)) etc.
  • the network-side equipment in the above-mentioned device embodiments corresponds to the terminal equipment and the network-side equipment or terminal equipment in the method embodiments, and the corresponding modules or units execute the corresponding steps.
  • the communication unit transmits the reception in the method embodiments.
  • the sending step other steps except sending and receiving can be executed by the processing unit (processor).
  • the processing unit processor
  • component used in this specification are used to denote computer-related entities, hardware, firmware, a combination of hardware and software, software, or software in execution.
  • the component may be, but is not limited to, a process, a processor, an object, an executable file, an execution thread, a program, and/or a computer running on a processor.
  • the application running on the computing device and the computing device can be components.
  • One or more components may reside in processes and/or threads of execution, and components may be located on one computer and/or distributed between two or more computers.
  • these components can be executed from various computer readable media having various data structures stored thereon.
  • the component may be based on, for example, a signal having one or more data packets (such as data from two components interacting with another component in a local system, a distributed system, and/or a network, such as the Internet that interacts with other systems through signals) Communicate through local and/or remote processes.
  • a signal having one or more data packets (such as data from two components interacting with another component in a local system, a distributed system, and/or a network, such as the Internet that interacts with other systems through signals) Communicate through local and/or remote processes.
  • the disclosed system, device, and method may be implemented in other ways.
  • the device embodiments described above are only illustrative.
  • the division of the units is only a logical function division, and there may be other divisions in actual implementation, for example, multiple units or components can be combined or It can be integrated into another system, or some features can be ignored or not implemented.
  • the displayed or discussed mutual coupling or direct coupling or communication connection may be indirect coupling or communication connection through some interfaces, devices or units, and may be in electrical, mechanical or other forms.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the solutions of the embodiments.
  • each unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist alone physically, or two or more units may be integrated into one unit.
  • the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium.
  • the technical solution of this application essentially or the part that contributes to the existing technology or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including Several instructions are used to make a computer device (which may be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in each embodiment of the present application.
  • the aforementioned storage media include: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk and other media that can store program code .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Un mode de réalisation de la présente invention concerne un procédé de session sécurisée et un appareil, qui sont supposés considérer davantage de scénarios d'application, satisfaire différentes exigences de service, et améliorer l'expérience de l'utilisateur. Le procédé peut comprendre : un dispositif de réseau d'accès qui reçoit un message de demande de session envoyé par un élément de réseau de gestion de session, le message de demande de session transportant une politique de sécurité de plan d'utilisateur d'un dispositif terminal et des informations sur un premier débit ; dans le cas où le dispositif de réseau d'accès ne peut pas effectuer la politique de sécurité de plan d'utilisateur en fonction du premier débit, le dispositif de réseau d'accès peut activer une protection d'intégrité selon un second débit sur la base des informations de politique de sécurité de plan d'utilisateur ou d'indication dans le message de demande de session, le second débit étant inférieur au premier débit.
PCT/CN2020/090240 2019-05-23 2020-05-14 Procédé et appareil de session sécurisée Ceased WO2020233496A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910432802.2 2019-05-23
CN201910432802.2A CN111988782B (zh) 2019-05-23 2019-05-23 安全会话方法和装置

Publications (1)

Publication Number Publication Date
WO2020233496A1 true WO2020233496A1 (fr) 2020-11-26

Family

ID=73437367

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/090240 Ceased WO2020233496A1 (fr) 2019-05-23 2020-05-14 Procédé et appareil de session sécurisée

Country Status (2)

Country Link
CN (1) CN111988782B (fr)
WO (1) WO2020233496A1 (fr)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117336711A (zh) * 2022-06-25 2024-01-02 华为技术有限公司 安全决策协商方法及网元
CN118055457A (zh) * 2022-11-17 2024-05-17 展讯通信(上海)有限公司 通信方法、计算机可读存储介质及通信装置

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140269613A1 (en) * 2013-03-18 2014-09-18 Nokia Siemens Networks Oy Integrity protection towards one CN after handovers involving multiple services to be handled by different CNs
CN109618335A (zh) * 2017-05-05 2019-04-12 华为技术有限公司 一种通信方法及相关装置

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109218325B (zh) * 2017-08-11 2020-03-10 华为技术有限公司 数据完整性保护方法和装置
DK3513584T3 (da) * 2017-10-02 2020-06-02 Ericsson Telefon Ab L M Access stratum-sikkerhed i et trådløst kommunikationssystem
WO2019095209A1 (fr) * 2017-11-16 2019-05-23 Zte Corporation Procédé et dispositif informatique pour réaliser la protection d'intégrité de données

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140269613A1 (en) * 2013-03-18 2014-09-18 Nokia Siemens Networks Oy Integrity protection towards one CN after handovers involving multiple services to be handled by different CNs
CN109618335A (zh) * 2017-05-05 2019-04-12 华为技术有限公司 一种通信方法及相关装置

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
ERICSSON: "Handling of maximum supported data rate per UE for integrity protection of DRBs", 3GPP TSG-SA WG3 MEETING #92 S3-182351, 24 August 2018 (2018-08-24), XP051541445, DOI: 20200731100409A *
ERICSSON: "UP security policy", 3GPP TSG-SA WG3 MEETING #91 S3-181309, 20 April 2018 (2018-04-20), XP051438412, DOI: 20200731100202A *
HUAWEI ET AL.: "Deletion of the 5GSM cause #8", 3GPP TSG-CT WG1 MEETING #116 C1-192228, 12 April 2019 (2019-04-12), XP051705420, DOI: 20200731100921A *

Also Published As

Publication number Publication date
CN111988782A (zh) 2020-11-24
CN111988782B (zh) 2022-04-12

Similar Documents

Publication Publication Date Title
US11477689B2 (en) Method and apparatus for establishing guaranteed bit rate (GBR) quality of service (QoS) flow in session
US20220330361A1 (en) Method for establishing connection and obtaining relay service code and communications apparatus
CN110830991B (zh) 安全会话方法和装置
WO2020200066A1 (fr) Procédé, système et appareil d'acquisition de paramètre de latence de paquet de données
WO2020052531A1 (fr) Procédé et appareil pour acquérir un contexte de sécurité
WO2019196643A1 (fr) Procédé de communication et appareil de communication
WO2020052613A1 (fr) Procédé de commutation et équipement terminal
US11310658B2 (en) Method and apparatus for determining status of terminal device, and device
WO2020151614A1 (fr) Procédé et appareil de protection de sécurité de plan utilisateur
CN107736055A (zh) 业务承载拥塞控制的方法及设备
US20220141664A1 (en) Data transmission method and apparatus in network slice architecture
CN116602042A (zh) 用于小数据传输的lch配置
WO2021062727A1 (fr) Procédé et appareil de redirection, dispositif terminal et dispositif de réseau
CN110225517B (zh) 一种信息发送方法、装置、系统以及计算机可读存储介质
WO2022174802A1 (fr) Procédé de mise à jour d'une clé cryptographique, et appareil
WO2022237857A1 (fr) Procédé de détermination de mode d'activation de protection de sécurité, procédé de communication et appareil de communication
US20220272577A1 (en) Communication method and communication apparatus
WO2017193368A1 (fr) Procédé et dispositif de réglage de débit de codage
WO2020233496A1 (fr) Procédé et appareil de session sécurisée
WO2020200297A1 (fr) Procédé et appareil de sélection d'élément de réseau de gestion de session
WO2019028794A1 (fr) Procédé et dispositif de détermination de chemin de service
CN112789896B (zh) 切换传输路径的方法及装置
EP4075859B1 (fr) Désactivation d'une connexion de plan utilisateur en cas de nombre maximal de sessions
WO2020042038A1 (fr) Procédé et dispositif de communication
WO2020087546A1 (fr) Procédé de transmission et procédé d'obtention d'informations de réseau, dispositif de réseau et dispositif terminal

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20810252

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20810252

Country of ref document: EP

Kind code of ref document: A1